]> git.ipfire.org Git - thirdparty/knot-resolver.git/commitdiff
distro/tests: update DNSSEC bogus test obs-knot-resolver-bs4hbr/deployments/1218
authorTomas Krizek <tomas.krizek@nic.cz>
Mon, 2 Nov 2020 10:17:59 +0000 (11:17 +0100)
committerTomas Krizek <tomas.krizek@nic.cz>
Mon, 2 Nov 2020 11:38:49 +0000 (12:38 +0100)
dnssec-failed.org domain uses RSA/SHA1 algorithm, which is considered
insecure by Fedora 33+ policy.

distro/tests/ansible-roles/knot_resolver/tasks/test_dnssec.yaml

index 990d4ca9423b8c2ad9a5204f0d00642faf39a2b9..52bbbb2f8e07cad72c472a6a04c2e66b533a6362 100644 (file)
@@ -1,15 +1,15 @@
 ---
 # SPDX-License-Identifier: GPL-3.0-or-later
-- name: dnssec_test dnssec-failed.org +cd returns NOERROR
+- name: dnssec_test bogussig.bad-dnssec.wb.sidnlabs.nl. +cd returns NOERROR
   tags:
     - test
-  shell: kdig +cd @127.0.0.1 dnssec-failed.org
+  shell: kdig +cd @127.0.0.1 bogussig.bad-dnssec.wb.sidnlabs.nl.
   register: res
   failed_when: '"status: NOERROR" not in res.stdout'
 
-- name: dnssec_test dnssec-failed.org returns SERVFAIL
+- name: dnssec_test bogussig.bad-dnssec.wb.sidnlabs.nl. returns SERVFAIL
   tags:
     - test
-  shell: kdig @127.0.0.1 dnssec-failed.org
+  shell: kdig @127.0.0.1 bogussig.bad-dnssec.wb.sidnlabs.nl.
   register: res
   failed_when: '"status: SERVFAIL" not in res.stdout'